The ERC-20 bridge of warp.green, a cross-chain messaging protocol, was exploited due to a vulnerability in its Chia-side Chialisp puzzle. The attacker minted worthless tokens, obtained validator signatures, and drained approximately $93,000 USDC from bridge contracts on Base and Ethereum.
The address labeled Bofur Capital lost $2M due to an address poisoning attack after withdrawing from Compound. A phisher sent a small USDC transaction to spoof the address, and the victim mistakenly copied the wrong address, leading to the drain. The stolen funds were swapped to 2M DAI.
A suspicious outflow of $1.284 million USDC was detected on August 11th from a vultisig-related address. Approximately $1.092 million USDC was swapped for ETH and deposited into Tornado Cash.
The owner privileges of a WEMIX$-related smart contract were compromised due to a private key leak, allowing an attacker to mint approximately 5.23 million WEMIX$ stablecoins, worth about $6.25 million. The stolen stablecoins were swapped and bridged out. Bridges and related services have been suspended.
Lien Finance, an Ethereum DeFi protocol, was exploited on July 24, 2026, due to a validation flaw in its BondMakerCollateralizedEth contract, leading to the minting of unbacked tokens and the draining of approximately $542K USDC.
DefiTuna Lending on Solana experienced a swap logic flaw exploit, resulting in a loss of approximately $580,000 and a deficit in the USDC lending pool. The vulnerability has been patched, and the team is investigating fund recovery.
Ostium, an RWA-focused perpetuals DEX on Arbitrum, suffered an oracle manipulation exploit due to a compromised oracle signer key, draining approximately $18 million USDC. Trading has been halted.
A legacy royalties contract associated with Royal.io on Polygon was exploited due to a logic flaw in reward/pro-rata royalty accounting, resulting in a loss of approximately $263,000 USDC.
The DIP token contract was exploited due to a missing return statement in the _transfer() function, causing double transfers and allowing an attacker to drain approximately $111,000 USDC.
Solana-based decentralized exchange Raydium disclosed a vulnerability in its deprecated AMM V3 program, which allowed an attacker to drain approximately $1.34 million from five inactive liquidity pools. No current users or active programs were affected, and Raydium will compensate losses from its treasury.
Fractal Protocol's USDF vault on Arbitrum was exploited due to a smart contract logic flaw, resulting in the loss of approximately 13,700 USDC.e. The exploit involved a flash loan and re-entrant calls that manipulated accounting issues.
Adshares Bridge was exploited on Ethereum, allowing an attacker to mint and dump fake wrapped ADS tokens, draining approximately $628K in ETH and USDC from liquidity pools. The project has offered a bounty for the return of funds.
ShapeShift's FOX Colony on Arbitrum was exploited via a smart contract vulnerability, resulting in the loss of approximately $132,700 in USDC and FOX tokens. The core exchange platform was unaffected, but the DAO/community treasury was impacted.
Aurellion Labs' Diamond Proxy contract on Arbitrum was exploited due to an uninitialized proxy vulnerability, allowing an attacker to take ownership and drain USDC. The project has paused operations and will reimburse users.
Aftermath Finance, a decentralized perpetuals trading platform on Sui, suffered a security exploit due to a flaw in its fee accounting logic, resulting in a loss of approximately $1.14 million in USDC. The protocol's perpetuals product was promptly paused.